Paragon Store Fixtures2026-07-17
interlockransomwareUnited States
Una brecha de seguridad afectó a Paragon Store Fixtures, una empresa especializada en diseños personalizados para establecimientos de lujo y sectores premium. El ataque, atribuido al grupo c...
Silvestri & Associates Insurance2026-07-04
playransomwareUnited States
El 4 de julio de 2026, la empresa Silvestri & Associates Insurance se vio afectada por un ataque cibernético relacionado con ransomware. Según los registros de seguridad, el grupo malicioso ...
Daily Dark Web: Call of Duty: Mobile Internal Offsets Allegedly Released A forum user has shared what they claim is an internal `offsets dump.cs` file for the global version of Call of Duty: Mobile (package: `com.activision.callofduty.shooter`). The post includes a public download link and states the file will be reposted if the original link becomes unavailable.2026-06-28
DailyDarkWebbreachUnited States
Daily coverage of dark web activities, cybercrime forums and underground market intelligence.
Ido Cohen: New Ransomware Group: Settra Settra has entered the ransomware landscape with 10+ published victims already listed on its leak site. Unlike groups that attempt to justify their actions, Settra openly states its motivation is simple: money. The group claims it does not target specific countries or industries—it targets organizations with exploitable security weaknesses.2026-06-27
ido_cohen2ransomwareUnknownT1566
Independent cyber threat research covering malware campaigns, phishing infrastructure and vulnerability exploitation.
Ido Cohen: Tracking the pulse of ransomware in 2026—these are the groups leading the global attack landscape right now: Qilin – 665 attacks The Gentleman – 453 attacks Akira – 290 attacks DragonForce – 245 attacks INC – 239 attacks Lockbit – 199 attacks Play – 154 attacks CLOP – 127 attacks NightSpire – 115 attacks CoinBase Cartel – 97 attacks Stay ahead of ransomware threats.2026-06-26
ido_cohen2ransomwareUnknownT1566
Independent cyber threat research covering malware campaigns, phishing infrastructure and vulnerability exploitation.
Ido Cohen: Stormous is back with increased activity. Recent victims have had their public websites defaced with a ransomware message displayed directly on the homepage—a pressure tactic sometimes used by ransomware groups to increase urgency and force negotiations. DarkFeed makes it easy to compare a ransomware group's leak site with the victim's public website in one place, helping analysts quickly identify attacks like these.2026-06-25
ido_cohen2ransomwareUnited StatesT1566
Independent cyber threat research covering malware campaigns, phishing infrastructure and vulnerability exploitation.
arid gopher indicators and references2026-06-18
arid-gopheriocUnknown
APTTrail mantiene indicadores publicos asociados a arid gopher. Aliases observados: arid gopher, arid viper, spyc23. Conteo por tipo: domain: 80, ipv4: 6, url: 2.
bisonal indicators and references2026-06-18
bisonaliocUnited States
APTTrail mantiene indicadores publicos asociados a bisonal. Aliases observados: bisonal, tonto, tontoteam. Conteo por tipo: domain: 232, file_path: 5, ipv4: 5, url: 4.
BackdoorDiplomacy indicators and references2026-06-18
backdoordiplomacyiocUnited StatesT1566
APTTrail mantiene indicadores publicos asociados a BackdoorDiplomacy. Aliases observados: BackdoorDiplomacy, Quarian, Turian. Conteo por tipo: domain: 67.